HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133084